Use‑After‑Free RCE in Foxit PDF Reader (CVE‑2026‑91816) Threatens Endpoint Security
What It Is — A use‑after‑free flaw in the AcroForm handling of Foxit PDF Reader allows a remote attacker to execute arbitrary code on the victim’s machine. The vulnerability is identified as CVE‑2026‑91816.
Exploitability — Requires user interaction (opening a malicious PDF or visiting a crafted page). CVSS 7.8 (High) with Network‑local vector, Low complexity, and Privilege‑None.
Affected Products — Foxit PDF Reader (all versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability management and timely patch deployment, a core control for maintaining a defensible audit trail.
- Evidence of patch status can be captured and presented in a Trust Center, satisfying multiple framework requirements (e.g., NIST CSF Identify, ISO 27001 Asset Management).
- Unpatched endpoints expose organizations to downstream data‑exfiltration risk, undermining supplier‑risk assurance and third‑party due‑diligence processes.
Recommended Actions
- Deploy Foxit’s September 2026 security update to all PDF Reader installations immediately.
- Verify patch compliance via automated asset inventory and endpoint monitoring.
- Incorporate the vulnerability into your vulnerability‑management program and map it to the relevant control objective (e.g., “Maintain up‑to‑date software”).
- Monitor logs for anomalous PDF processing activity that could indicate exploitation attempts.